Sobre este puesto de 2026-0091 Exercise Configuration and Change Management Support (NS) - TUE 11 Aug en EMW, Inc.
Deadline Date: Tuesday 11 August 2026
Requirement: Exercise Configuration and Change Management Support
Location: 100% onsite in Bydgoszcz, POL
Period of Performance: 2026 BASE: 01 October 2026 - 31 December 2026.
2027 Option: 1 January 2027 until 31 December 2027.
2028 Option: 1 January 2028 until 31 December 2028.
Required Security Clearance: NATO SECRET
1. INTRODUCTION
The Directorate of CIS Support Units (DCSU) is responsible for the delivery of end-to-end Communication and Information Systems (CIS) services across NATO commands through its CIS Support Units (CSUs). These services include installation, operation, maintenance and support of CIS capabilities required to enable NATO missions in peacetime, crisis and war.
CSU Bydgoszcz provides CIS services in support of local and deployed Operational Partners, ensuring that CIS systems and end-user services are delivered in a reliable, secure and operationally effective manner. The Service Management Branch (SMB) is responsible for the governance, coordination and oversight of service management processes within CSU Bydgoszcz, including Configuration Management and Change Management, and shall provide the operational direction, prioritization and validation of the services delivered under this Statement of Work.
This Statement of Work defines the acquisition of Exercise Configuration and Change Management Support services to improve configuration data quality, support controlled change implementation, maintain physical connectivity records in Patch Manager and ensure supporting documentation is updated and available.
2. BACKGROUND
CSU Bydgoszcz supports NCIA Operational Partners through the delivery and maintenance of assigned CIS products and services. This includes support to day-to-day operations and exercise-related CIS activities.
The Configuration and Change Management (C&ChM) function ensures the integrity, traceability and controlled evolution of IT services and infrastructure within the NCIA operational environment. It supports accurate configuration baselines, effective change control processes and alignment with ITIL-based service management practices.
To maintain operational continuity and compliance with established procedures, additional support is required to assist in the coordination, documentation and tracking of configuration items and change requests within the IT Service Management (ITSM) toolset.
3. OBJECTIVE
The objective of this Statement of Work is to obtain Exercise Configuration and Change Management Support services that contribute to the effective delivery of C&ChM activities within CSU Bydgoszcz. The Statement of Work is to obtain services ensuring the following:
- Accurate and timely update of configuration records in the CMDB.
- Controlled administrative support to approved Work Orders (WOs), Change Requests (CRQs) and related tasks.
- Accurate update of Patch Manager records for physical cable plant, including fibre and copper connectivity.
- Improved documentation and knowledge availability through lessons learned and knowledge-based updates.
- Traceable reporting of completed outputs and identified discrepancies.
All services shall be delivered under the direction and prioritisation of the SMB and in close coordination with the Purchaser's (NCIA) designated Points of Contact.
4. SCOPE OF WORK
4.1 General
The Contractor personnel shall deliver Exercise Configuration and Change Management Support services in a structured, measurable and outcome-based manner. All activities shall be aligned with approved processes, tools and governance frameworks defined by the Purchaser.
All services shall be delivered in an outcome-based manner, with clearly defined deliverables, measurable outputs and traceable records of completion. The Contractor personnel shall ensure that all activities are properly documented in relevant systems and that all outputs are auditable and verifiable.
The Contractor personnel shall operate as an integral part of the SMB, supporting day-to-day operational requirements as well as preparation and execution of CIS support activities for exercises and other operational events.
4.2 Governance and Prioritisation
The Contractor personnel shall perform all activities under the direction of the Purchaser, who will assign, prioritize and validate tasks through established service management processes.
All work shall be initiated based on authorized requests, including but not limited to Work Orders (WOs), service requests, tasking instructions or equivalent mechanisms defined by the Purchaser. The Contractor personnel shall ensure that all assigned tasks are executed within agreed timelines and in accordance with operational priorities.
The Contractor personnel shall maintain regular communication with the Purchaser's Points of Contact, provide status updates on ongoing activities and promptly report any issues, risks or deviations that may impact service delivery.
4.3 Support to Other CIS Service Areas
In addition to core responsibilities within the SMB, the Contractor personnel may be required to provide support to other CIS service areas within CSU Bydgoszcz, where such support is directly related to C&ChM activities support and remains aligned with other service domains within the defined technical scope of this SoW.
Such support may include assistance with Infrastructure and platform services, Application Management, Cyber Security or execution of related operational tasks, as directed by the Purchaser. The Contractor personnel shall ensure consistency of data and traceability across systems and domains where applicable.
5. SERVICE AREAS AND DELIVERABLES
The services shall be delivered in line with the SMB operational priorities and in accordance with NCIA policies, procedures, and technical standards. The Contractor personnel shall provide the deliverables defined below, ensuring that all outputs are measurable, traceable, and subject to formal acceptance by the Purchaser, against the mentioned KPIs.
Delivery will generically be assessed based on timeliness, quality of the outputs, and compliance with agreed requirements.
5.1 Exercise Configuration and Change Management Support Deliverables
Deliverable D1: CMDB Data Quality and Updates - Maintain accurate records of all Configuration Items (CIs), including workstations, laptops, network connections and software used during exercises; ensure the CMDB reflects the real operational environment by regularly updating CIs; this includes adding new items, modifying existing ones, and removing obsolete entries.
Acceptance Criteria A1: All relevant CIs are recorded and updated following deployment, movement or change; records reflect actual field setup; missing or outdated entries are corrected when identified.
Deliverable D2: Asset and Equipment Tracking for Exercises - Maintain a clear overview of all CIS equipment used during exercises (e.g., end user devices, deployable kits, network gear), including assignment, location and status; support preparation, deployment and return phases.
Acceptance Criteria A2: Asset inventory available and up to date at all times; each item traceable to a user/location/status; check-in/check-out records maintained; discrepancies logged and resolved within the defined SLA; no critical equipment unaccounted for during exercises.
Deliverable D3: Change Implementation, Coordination & Reporting - Support coordination of planned changes by organizing schedules, confirming readiness with stakeholders, and ensuring approvals are in place; help avoid conflicts during critical periods such as exercise execution; maintain the change register tool (ITSM) by logging, categorizing, and updating all Requests for Change (RFCs) related to exercise CIS services and assets; ensure proper classification (standard, normal, emergency).
Acceptance Criteria A3: Each implemented change includes a record of execution and outcome; any deviation from plan is documented; issues are reported; change status is updated promptly after execution; all RFCs are recorded in the system with correct classification and required details; status is kept current throughout the lifecycle; no change affecting services is performed without a registered RFC.
Deliverable D4: Pre-Exercise and Post-Exercise Configuration Verification and Updates - Support validation of systems before exercises by checking that configurations, versions, and connections match the expected setup; work with engineers to identify missing components or inconsistencies; after exercises, ensure that all temporary changes, deployments, and workarounds are either reverted or properly documented; update CMDB and asset records to reflect the final state.
Acceptance Criteria A4: Pre-exercise checklists completed within the agreed timeline; deviations documented and assigned; critical issues resolved or formally accepted before start; confirmation of readiness communicated to stakeholders; evidence of checks retained; CMDB and asset records aligned with final state; outstanding issues logged and tracked.
Deliverable D5: Software and License Tracking - Maintain an up-to-date overview of installed software and associated licenses for systems used during exercises and operations; this includes recording software versions, license types, allocation to systems/users, and tracking validity/expiry; support teams in identifying missing, unused or non-compliant licenses.
Acceptance Criteria A5: Software records linked to relevant CIs in the CMDB where applicable; license information (type, owner, expiry) recorded and kept up to date; periodic checks performed to identify discrepancies or expirations; no critical license gaps impacting operations; issues (e.g., expired or missing licenses) tracked and followed up until resolved.
Deliverable D6: Configuration Control & Service Impact - Support Service Configuration Management by verifying that deployed CIS assets match their recorded configuration and approved baselines; assist in identifying and communicating the potential service impact of planned changes on exercise operations and users.
Acceptance Criteria A6: Physical and logical checks confirm alignment between deployed assets and CMDB records; discrepancies are logged and followed up; no critical assets remain unverified during exercise phases; changes with potential service impact are clearly flagged; affected services and users are identified; relevant stakeholders are informed before implementation.
Deliverable D7: Documentation of Changes and Activities - Maintain clear and simple records of what was changed, when, and why; ensure that information in tickets, CMDB, and shared documents is understandable and usable by others (not just technically correct); provide data and basic reports on configuration and change activities when requested (e.g., list of changes during an exercise, asset lists, configuration status).
Acceptance Criteria A7: Documentation is complete, clear, and consistently formatted; stored in agreed repositories; accessible to all stakeholders; periodic reviews show no major gaps or ambiguities; reports delivered within agreed timelines; data consistent across CMDB, ticketing and asset tools; able to demonstrate traceability of selected samples.
Deliverable D8: Patch Manager Cable Plant Documentation Updates - Maintenance of physical connectivity documentation (copper and fibre).
Acceptance Criteria A8: Patch Manager updated; ports marked used/free; assets recorded; traceability to change requests confirmed.
6. DELIVERABLE ACCEPTANCE, REPORTING AND PAYMENT
A single deliverable is defined under this Statement of Work as the provision of Exercise Configuration and Change Management support services covering all activities described in Sections 4 and 5.
Each payment is subject to the following acceptance conditions:
The corresponding deliverable has been formally submitted and accepted by the Purchaser.
The associated KPIs have been achieved for the reporting period. Where a KPI is not fully met, payment may be reduced proportionally in accordance with the contractual performance mechanism.
All supporting evidence (e.g., tickets, deployment reports, patch compliance reports, asset records, account management logs, readiness checklists and audit logs) has been provided.
Any identified deficiencies or review comments have been addressed before final acceptance.
Acceptance shall be formalized through the Delivery Acceptance Sheet (DAS), signed by the Purchaser's representative. Payment shall be made only upon successful delivery of agreed outputs, submission of required reports, and formal acceptance of deliverables by the Purchaser.
Monthly payments represent partial consumption of the total contract value. Deliverables that do not meet acceptance criteria shall be corrected and resubmitted without additional cost.
6.1 Key Performance Indicators (KPIs)
The Contractor personnel's performance shall be evaluated on a monthly basis against the following measurable Key Performance Indicators:
CMDB & Configuration (Weight 20%): KPI 1.1: greater than or equal to 98% accuracy of verified Configuration Items (CIs). KPI 1.2: 100% of updates completed within 2 working days of change.
Asset Tracking (Weight 15%): KPI 2.1: 100% traceability of all exercise-related equipment. KPI 2.2: Discrepancies resolved within 2 working days.
Change Management (Weight 20%): KPI 3.1: greater than or equal to 95% of changes implemented without major incidents. KPI 3.2: 100% of change records updated within 1 working day.
Exercise Support (Weight 15%): KPI 4.1: 100% of pre-exercise checklists completed within agreed timelines. KPI 4.2: greater than or equal to 95% of critical issues resolved prior to exercise start.
Software & Licensing (Weight 10%): KPI 5.1: 100% of software mapped to relevant CIs. KPI 5.2: 0 critical license expirations impacting operations.
Documentation (Weight 10%): KPI 6.1: 100% documentation completeness and audit readiness. KPI 6.2: 100% of reports delivered within agreed timelines.
Patch Management (Weight 10%): KPI 7.1: 100% update of physical connectivity documentation. KPI 7.2: 0 critical ports unidentified or undocumented.
6.2 Payment Model (Outcome-Based)
A delivery-based payment model balances delivery, ensuring that all deliverables, supporting documentation, quality assurance findings, and contractual obligations are satisfactorily completed before final payment.
This allows a transparent, objective, auditable procurement practice by linking payment directly to measurable performance while maintaining incentives for quality, governance, and timely delivery.
For each deliverable, a Deliverable KPI Score is calculated as a weighted average of the two deliverable-specific KPIs (50% each): DPS = (KPI1 x 50%) + (KPI2 x 50%). Example: DPS = (98% x 50%) + (92% x 50%) = 95%.
To assess whether a KPI has been attained, the following monthly score scale applies:
Monthly Score 95% or higher: 100% payment.
Monthly Score 90-94%: 95% payment.
Monthly Score 80-89%: 85% payment.
Monthly Score 70-79%: 70% payment.
Monthly Score below 70%: 0% payment (mandatory remediation required).
The deliverables are then weighted as follows for the purpose of the monthly payment calculation:
D1 - Configuration Item (CI) and CMDB Management (Weight 20%): Payment Milestone: Upon acceptance of monthly CMDB update report and audit results. Acceptance Criteria: KPIs achieved; CMDB reflects approved changes; audit confirms required accuracy.
D2 - CIS Asset Management During Exercises (Weight 15%): Payment Milestone: Upon completion of each exercise and acceptance of asset accountability report. Acceptance Criteria: Asset register complete; deployment/return records verified; KPIs achieved.
D3 - Change Coordination and RFC Management (Weight 15%): Payment Milestone: Upon acceptance of monthly Change Management report. Acceptance Criteria: RFCs correctly logged, classified and approved; KPIs achieved.
D4 - Configuration Validation and Post-Exercise Restoration (Weight 15%): Payment Milestone: Following completion of each exercise and acceptance of restoration report. Acceptance Criteria: Validation completed; temporary configurations reconciled; CMDB updated; KPIs achieved.
D5 - Software Asset and License Management (Weight 10%): Payment Milestone: Upon acceptance of monthly Software Asset Management report. Acceptance Criteria: Software inventory current; licensing compliance demonstrated; KPIs achieved.
D6 - Service Configuration Management Support (Weight 10%): Payment Milestone: Upon acceptance of monthly baseline verification report. Acceptance Criteria: Baseline compliance verified; service impact assessments completed; KPIs achieved.
D7 - Configuration Documentation and Reporting (Weight 10%): Payment Milestone: Upon acceptance of monthly Configuration Management report. Acceptance Criteria: Documentation complete, traceable and reports delivered on time.
D8 - Physical Connectivity Documentation (Weight 5%): Payment Milestone: Upon acceptance of updated connectivity documentation following changes or exercise completion. Acceptance Criteria: Cabling documentation updated and validated; KPIs achieved.
Total combined weight of all deliverables: 100%.
Monthly payment is calculated as the sum of each Deliverable KPI Score multiplied by its deliverable weight, applied to the monthly Not to Exceed (NTE) value.
6.3 Acceptance Conditions
Monthly deliverables shall be accepted only if all agreed outputs meet defined acceptance criteria.
A complete Monthly Report must be submitted, including a summary of activities performed, supporting evidence (tickets, CMDB records, RFCs), and KPI measurement and scoring.
Formal acceptance is granted via the Delivery Acceptance Sheet (DAS).
Non-compliant deliverables shall be corrected and resubmitted at no additional cost, and may impact the monthly payment.
7. COORDINATION AND GOVERNANCE
The Contractor personnel shall coordinate all activities with the SMB and shall participate in meetings as required by the Purchaser.
The Contractor personnel shall provide updates on progress, highlight risks or issues, and support coordination with other teams where necessary; regular coordination shall include progress reviews, issue escalation, validation of priorities, and alignment with operational requirements.
The Contractor personnel shall ensure compliance with all applicable governance frameworks and procedures.
8. SCHEDULE
The service shall start upon contract signature.
The BASE period of performance shall be from 01 October 2026 to 31 December 2026.
The NCIA may exercise options for continued service delivery as follows:
- OPTION 1: 1 January 2027 to 31 December 2027.
- OPTION 2: 1 January 2028 to 31 December 2028.
The exercise of options is subject to operational needs and available funding.
9. CONSTRAINTS
All activities shall be performed in accordance with NATO and NCIA standards, policies, security directives and procedures.
The Contractor personnel shall not perform activities outside the defined scope without prior authorisation from the Purchaser.
All artefacts shall be stored in approved tools.
Activities shall comply with service and configuration management practices.
10. SECURITY
The security classification of the service will be up to NATO SECRET.
The contractor personnel providing the services under this SOW is required to hold a valid NATO SECRET security clearance.
11. PRACTICAL ARRANGEMENTS
The Contractor personnel shall provide services on-site at CSU Bydgoszcz, Poland.
The Contractor personnel shall ensure the availability of the required expertise.
No travel outside Poland is required.
12. QUALIFICATIONS
[See Requirements]
13. LANGUAGE PROFICIENCY
[See Requirements]
Requirements
10. SECURITY
- The contractor personnel providing the services under this SOW is required to hold a valid NATO SECRET security clearance.
12. QUALIFICATIONS
Mandatory:
- Proven hands-on experience in configuration management, change management, asset management or a similar IT support/coordination role, and comfortable working in operational environments where accuracy, follow-up and documentation are critical.
- Practical experience updating and maintaining CMDB records and handling change or incident tickets in tools such as ITSM, JIRA or similar, and able to ensure data quality, consistency and traceability across systems.
- Good working knowledge of core configuration and change management principles (e.g., baselines, CI relationships, change lifecycle, approvals), with the ability to apply these in day-to-day work, and familiarity with ITIL practices.
- Ability to track multiple tasks, follow up with different teams and keep activities moving, and comfortable coordinating between technical staff, stakeholders and management in a structured environment, with an understanding of infrastructure documentation.
- Strong analytical and documentation skills, with the ability to document and report activities accurately.
- Very good working knowledge of licensing models (e.g., VMware, Microsoft, Linux, etc.), understanding of common software types (e.g., operating systems, standard enterprise tools, client/server applications) and how licensing works in practice (e.g., per user, per device, subscription-based), and the ability to maintain license records, track usage, and identify obvious inconsistencies such as missing, expired or unused licenses.
- Familiarity with CIS (Communication and Information Systems) environments, with a basic understanding of IT infrastructure such as networks, servers and end-user systems.
- Ability to produce clear, structured and usable documentation (tickets, records, reports), with information that is understandable and traceable by others, including for audit purposes.
- Comfortable following defined procedures, governance frameworks, and tool usage guidelines, while ensuring all actions are properly recorded and auditable.
Desirable:
- Experience in NATO or NCIA environments.
- Knowledge of ITIL practices.
- Experience supporting C&ChM in preparation for and during exercises, deployments or large-scale IT operations.
13. LANGUAGE PROFICIENCY
- The Contractor personnel shall demonstrate English language proficiency at a minimum of STANAG 6001 Level 3 (or equivalent CEFR B2/C1 level).